Nat - Siemens SIMATIC NET SCALANCE S615 Configuration Manual

Industrial ethernet security web based management
Hide thumbs Also See for SIMATIC NET SCALANCE S615:
Table of Contents

Advertisement

Technical basics

2.3 NAT

2.3
NAT
NAT (Network Address Translation) is a method of translating IP addresses in data packets.
With this, two different networks (internal and external) can be connected together.
A distinction is made between source NAT in which the source IP address is translated and
destination NAT in which the destination IP address is translated.
IP masquerading
IP masquerading is a simplified source NAT. With each outgoing data packet sent via this
interface, the source IP address is replaced by the IP address of the interface. The adapted
data packet is sent to the destination IP address. For the destination host it appears as if the
queries always came from the same sender. The internal nodes cannot be reached directly
from the external network. By using NAPT, the services of the internal nodes can be made
reachable via the external IP address of the device.
IP masquerading can be used if the internal IP addresses cannot or should not be forwarded
externally, for example because the internal network structure should remain hidden.
You configure masquerading in "Layer 3" > "NAT" > "IP Masquerading (Page 138)".
NAPT
NAPT (Network Address and Port Translation) is a form of destination NAT and is often
called port forwarding. This allows the services of the internal nodes to be reached from
external that are hidden by IP masquerading or source NAT.
Incoming data packets are translated that come from the external network and are intended
for an external IP address of the device (destination IP address). The destination IP address
is replaced by the IP address of the internal node. In addition to address translation, port
translation is also possible.
The options are available for port translation:
from
a single port
a single port
a port range
a port range
a port range
a single port
24
to
Response
the same
If the ports are the same, the frames will be forwarded without port
port
translation.
a single port
The frames are translated to the port.
a single port
The frames from the port range are translated to the same port (n:1).
the same
If the port ranges are the same, the frames will be forwarded without
port range
port translation.
another port
The frames are translated to any free port from the target range.
range
With individual connection, they are normally translated to the first port
in the target range.
If there are connections at the same time, the round robin method is
used to translate to a free port in the target range.
a port range
The frames are translated to any free port from the target range. With
individual connection, they are normally translated to the first port in
the target range. If there are connections at the same time, the round
robin method is used to translate to a free port in the target range.
SCALANCE S615 Web Based Management
Configuration Manual, 05/2015, C79000-G8976-C388-02

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents